CVE-2023-0829: Plesk

Critical severity, CVSS 9.0. EPSS: 0.6% chance of exploitation in the next 30 days.

Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

Affected products

  • Plesk Plesk: from 17.0, up to and including 18.0.31

Published 2023-09-20. Last modified 2026-06-17.